Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0897 | `silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted graphql query to execute a denial of service attack against a website which has a publicly exposed graphql endpoint. This mostly affects websites with particularly large/complex graphql schemas. Users should upgrade to `silverstripe/graphql` 4.2.3 or 4.1.2 to remedy the vulnerability. |
Github GHSA |
GHSA-67g8-c724-8mp3 | DDOS attack on graphql endpoints |
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-25T14:55:43.730Z
Reserved: 2023-03-10T18:34:29.226Z
Link: CVE-2023-28104
Updated: 2024-08-02T12:30:24.268Z
Status : Modified
Published: 2023-03-16T16:15:12.750
Modified: 2024-11-21T07:54:24.717
Link: CVE-2023-28104
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA